Asahi Group Holdings, one of Japan's largest brewery and food companies, suffered a significant ransomware attack that severely disrupted its domestic operations. The breach was first disclosed on September 29, when Asahi immediately shut down its manufacturing operations and isolated affected systems to contain the incident. This rapid response led to a halt in ordering and shipment systems, as well as the suspension of call-center operations across the brewery, soft drink, and food divisions. The disruption resulted in a shortage of Asahi's popular beer brands in Japan, impacting both retailers and consumers. Four days after the initial disclosure, the Qilin ransomware-as-a-service group claimed responsibility for the attack, posting screenshots purportedly showing internal Asahi documents as evidence. Asahi's CEO, Atsushi Katsuki, publicly apologized for the shutdown and assured stakeholders that the company was working diligently to restore systems and resume normal operations. The company established an Emergency Response Headquarters to investigate the nature and scope of the data breach, with ongoing efforts to determine whether unauthorized data transfers occurred. External cybersecurity experts were brought in to assist with the investigation and recovery process. Asahi began implementing manual operations to maintain some level of product supply and announced plans for a gradual resumption of call center activities. The company stated that the impact of the system disruption was limited to Japan, and no clear timeline for full recovery was provided. The financial impact of the incident for the fiscal year 2025 had not yet been detailed at the time of reporting. The attack on Asahi is part of a broader trend of increasing ransomware incidents targeting manufacturers and critical supply chains in the Asia Pacific region. The incident highlights the vulnerability of industrial control systems and operational technology environments to ransomware threats. Asahi's experience underscores the importance of rapid incident response, transparent communication, and collaboration with cybersecurity professionals during major cyber crises. The company continues to investigate the full extent of the breach and is working to restore all affected systems as quickly as possible. The attack has raised concerns about the resilience of food and beverage supply chains in the face of sophisticated cyber threats. Asahi's efforts to implement alternative measures and manual processes demonstrate the challenges organizations face in maintaining operations during prolonged system outages. The incident serves as a warning to other manufacturers about the growing risks posed by ransomware groups targeting critical infrastructure and supply chains.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
By 2025-10-08, Asahi reported that its Japanese subsidiaries had resumed full or partial production and that product shipments were back underway. The company said service restoration was ongoing as it worked to maintain supply through alternative measures.
After Qilin's claim, Asahi stated that data suspected of being transferred without authorization had been found online and that it was investigating the scope of any exposure. The company said it would notify affected parties if impacts were confirmed and that there was no indication other data and systems were affected beyond impacted technology assets in Japan.
Around 2025-10-07, the Qilin ransomware group claimed responsibility for the Asahi attack on its leak site. The group alleged it exfiltrated about 27 GB of data, including employee, financial, budget, and planning documents, and published screenshots or samples as proof.
On 2025-10-03, Asahi confirmed the incident was a ransomware attack after detecting its servers had been targeted. The company said it established an Emergency Response Headquarters, isolated affected systems, and CEO Atsushi Katsuki publicly apologized while recovery efforts continued.
On 2025-09-29, Asahi Group Holdings disclosed a cyberattack affecting its Japanese operations. The incident disrupted ordering and shipment systems and suspended call-center and customer service functions, contributing to domestic beer supply issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedarkreading.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.